T09 · Insecure Skill Coding Practices
- Location
SKILL.md:52- Finding
User-Controlled Prompt Embedded in Executable Python Source
- Content
View full analysis
" WIDTH=1024 HEIGHT=768 SEED="" # optional: "42" curl -s --max-time 180 \ "https://image.pollinations.ai/prompt/$(python3 -c "import urllib.parse; print(urllib.parse.quote('$PROMPT'))")?width=$WIDTH&height=$HEIGHT&nologo=true${SEED:+&seed=$SEED}" \ -o /tmp/generated_image.jpg ``` ### Technical Analysis The image prompt originates from user input and is interpolated directly into Python source code passed to `python3 -c`: ```python urllib.parse.quote('$PROMPT') ``` Although the prompt is held in a shell variable, its value is expanded inside the Python program. A single quote in the prompt can terminate the Python string literal. An attacker can then append Python statements and comment out the remaining source. This is a code-injection vulnerability rather than ordinary URL manipulation. Shell quoting does not make the operation safe because the expanded value is treated as part of Python source code. A malicious prompt can follow a structure conceptually similar to: ```text '); __import__('os').system(''); # ``` The exact payload may require adjustment for the surrounding expression, but the vulnerable boundary permits attacker-controlled Python statements. ### Attack Path 1. An attacker asks the Agent to generate an image using a prompt containing a single quote and injected Python syntax. 2. The Agent extracts the entire attacker-controlled description into `PROMPT`. 3. The shell expands `$PROMPT` inside the argument supplied to `python3 -c`. 4. The injected single quote closes the intended Python string. 5. The remaining attacker-controlled text is interpreted as Python code. 6. Python executes an operating-system command through funct ...[truncated 1002 chars]- Remediation
View remediation
